Compliance Specialist, IT/Tech
Listed on 2026-07-13
-
IT/Tech
Cybersecurity, Information Security & Data Protection, IT Consultant
IT Security Risk Auditor
Location: Must be within 100 miles from Lexington, MA.
Clearance Level: Must be able to obtain an Active Secret Clearance to be considered. Must be US Citizen.
About the RoleAt Aquila Technology, you will see our team’s passion every day, whether we are building a robust, policy‑compliant IT system or stress‑testing a system to identify gaps and security vulnerabilities. To own the advantage, we ensure our team owns results and gets the work done right the first time by deploying smart, purposeful solutions that work. Aquila is the right people with the right skills driving the right outcomes.
We call this the Aquila Advantage.
Aquila Technology is seeking an IT Security Risk Auditor to join its team in support of one of the nation’s premier defense research organizations. The team’s overall mission is to enable research and development while keeping the organizations community safe and secure through the protection of information, network, facilities and personnel.
The IT Security Risk Auditor will perform audits of classified and unclassified Information Systems (IS) to ensure that they are being maintained in a compliant manner and are following applicable laws and government regulations, such as NISPOM guidelines, NIST standards, CMMC, DAAPM and organizational Information System Security Procedures. The candidate must be knowledgeable in fundamental computer security principles and policies.
ResponsibilitiesThe IT Security Risk Auditor will maintain and audit programs to validate compliance with various government regulations and organizational information security policies. Responsibilities include conducting comprehensive assessments of the management, operation, monitoring and technical security controls employed within or inherited by Information Systems to determine the overall effectiveness of the controls with respect to meeting the security requirements of the Authorization to Operate (ATO) or other government regulation or contractual requirement for the system.
The role also involves conducting open‑source and internal research to identify current threat indicators, exploits, and vulnerabilities.
- Bachelor’s degree in Computer Science, Information Technology, Computer Information Systems, or related field with a minimum of seven (7) years’ experience conducting risk assessments.
- Experience in compliance auditing, security reviews, or vulnerability assessments.
- Technical experience and skills, coursework completed toward a degree, and industry IT certifications (e.g., CISSP, CISA) may be considered substitutes for education and experience.
- In‑depth knowledge of information security principles and policies such as RMF, NIST SP 800‑171 and STIGs.
- Ability to read, understand and apply government regulations, policies and procedures such as NISPOM, 32 CFR Part 117, FAR/DFARS Safeguarding CUI series (252.204‑7012, etc.), and NIST 800‑53/800‑171.
- Working experience directly related to Assessment and Authorization using at least one of the following:
- NIST 800‑53/Risk Management Framework (RMF)
- Joint Special Access Program (SAP) Implementation Guide
- NIST SP 800‑171 Understanding of CMMC Framework
- NISPOM Chapter 8
- Information Assurance Certifications preferred (CISSP/CISA, Security+, CCP/CCA, or other industry‑recognized certification).
- Direct experience with DCSA facility compliance reviews and security audits.
- Degree Level: Bachelor’s Degree
- 7 years Compliance & Auditing
- 7 years Document audit findings, including non‑compliance issues or deviations
- 7 years Identify potential compliance issues and recommend policy/procedure changes
- 3 years IT system security compliance (NIST, PCI, HIPAA, CMMC)
- 7 years Support preparation for audit/review activities
- 3 years Government Policy/Regulations
- 3 years STIG Compliance
- 3 years NISPOM 32 CFR Part 117 experience
- 3 years NIST 800‑171
- 3 years NIST 800‑53
- 3 years Risk Management Framework (RMF)
- 7 years MS Suite (Excel, PowerPoint)
- Strong Verbal and Written Communication
- Strong Time Management
- Certification:
Security+ CE, CASP, CISSP, or similar security certification. - Cybersecurity Maturing Model Compliance (CMMC).
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).